{"id":"CVE-2025-9222","title":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploitin…","summary":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploitin…","severity":"high","cvss":8.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","cwe":["CWE-79","CWE-79"],"vendor":"gitlab","product":"gitlab","affected":["gitlab >= 18.2.2, < 18.5.5","gitlab >= 18.6.0, < 18.6.3","gitlab = 18.7.0"],"patched":["gitlab 18.6.3"],"published":"2026-01-09","updated":"2026-06-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-9222","references":[{"url":"https://about.gitlab.com/releases/2026/01/07/patch-release-gitlab-18-7-1-released/","label":"cve@gitlab.com"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/562561","label":"cve@gitlab.com"},{"url":"https://hackerone.com/reports/3297483","label":"cve@gitlab.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-9222","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2428222","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9222.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"tags":["nvd"],"epss":0.0043,"epssPercentile":0.3668,"ingestedAt":"2026-06-30T13:26:50.271Z","slug":"CVE-2025-9222","body":"## Overview\n\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.\n\n## Affected\n\n- `gitlab >= 18.2.2, < 18.5.5`\n- `gitlab >= 18.6.0, < 18.6.3`\n- `gitlab = 18.7.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `gitlab 18.6.3`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":47.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}